Reference Material

Consolidation of Comments/Responses on AML/ATF General Guidance Notes (2016-06-03)

Bermuda Monetary Authority (BMA) · Bermuda

In force

Current version last checked: 2026-07-07

Summary

This document is the Bermuda Monetary Authority's consolidated record of stakeholder comments received on its revised AML/ATF General Guidance Notes (issued for consultation in February 2016) together with the Authority's responses and resolutions. It is not itself a piece of legislation or a standalone set of rules, but it explains how the BMA intends to amend, clarify, or retain provisions of the Guidance Notes following industry feedback, and confirms several supervisory expectations for AML/ATF Regulated Financial Institutions (RFIs).

  • SAR filing standard: The Authority agreed that the three-pronged test (belief/knowledge, suspicion, reasonable grounds to suspect) for filing Suspicious Activity Reports is not supported by current Bermuda legislation (POCA only provides a two-pronged test) and will be removed from the Guidance Notes pending legislative amendment.
  • Consent regime: The Authority agreed to add guidance on the amended consent provisions in Sections 43-45 of POCA and Section 12 of ATFA, and to make cross-references to these sections consistent throughout the Guidance Notes.
  • Compliance Officer seniority: The Authority agreed to amend the Guidance Notes so the Compliance Officer need only be appointed at managerial level (reporting to senior management), rather than requiring a Director or Senior Executive appointment.
  • Independent audit: RFIs are expected to conduct an independent AML/ATF audit separately from general operational audits, at least once a year, with more frequent audits where warranted by risk; the audit may be staggered into smaller reviews across the year provided all required areas are covered within that year.
  • Periodic reporting to senior management: Senior management must be advised of AML/ATF compliance matters at least once per year, with the exception report forming part of this standard periodic report.
  • Risk-based approach: RFIs must structure their AML/ATF programme using a risk-based approach; the Authority declined to prescribe a single minimally acceptable programme, and clarified that inherent/residual risk assessment should generally be applied at the customer level rather than the portfolio level.
  • Overseas operations of financial groups: Where Bermuda is the host jurisdiction and the parent's home jurisdiction has equivalent or stronger AML/ATF standards, the Bermuda RFI may be permitted to rely on the parent's AML/ATF programme, but the RFI must demonstrate this equivalence to the Authority before doing so.

Several stakeholder queries (for example on tax evasion suspicions, sector-specific insurance guidance in Annex II, and inclusion of the Governor in Annex V) were noted but not incorporated, either because they fall outside the scope of the Guidance Notes or because separate consultation processes were already underway. The document itself does not set new commencement dates or transition periods; changes to the Guidance Notes were to follow once related legislative amendments (e.g. to POCA) were made.

Key obligations

  • RFIs must conduct an independent AML/ATF audit, separate from general operational audit, at least once a year (more frequently if warranted by risk).
  • RFIs must ensure senior management receives a periodic AML/ATF compliance report at least once per year.
  • RFIs must structure their AML/ATF programme using a risk-based approach, assessing risk at the customer level.
  • RFIs relying on a parent company's AML/ATF programme for overseas operations must demonstrate to the Authority that the parent's home jurisdiction standards are equivalent to or exceed Bermuda's before doing so.
  • Compliance Officers must be appointed at least at managerial level and report to senior management.

Applies to

AML/ATF Regulated Financial Institutions (RFIs), banks, insurers, other financial institutions subject to Bermuda AML/ATF legislation

Deadlines

  • at least once a year: Frequency required for the independent AML/ATF audit of an RFI's programme
  • at least once per year: Frequency required for the periodic AML/ATF compliance report to senior management

Topics

Version history

2026-07-07

source file (current)